Dolomite Hack

REPORTED LOSS $1.8M
Medium Invalid-order signature-check bypass through a legacy approved trade delegate Ethereum

What happened

Dolomite's deprecated Ethereum legacy product was exploited for about $1.8 million through lingering approvals to an old Loopring Trade Delegate and an invalid-order signature-validation bypass. The legacy system had been spun down in 2020; this was not an attack on Dolomite's current deployment. Dolomite recovered 90% of affected assets and used treasury funds to reimburse every victim.

Technical Root Cause

The legacy Loopring and Dolomite architecture relied on downstream order validation to revert. Defensive and gas-optimization handling allowed malformed orders to continue, while a partially-filled-order state bypassed signature verification. Lingering user approvals supplied the authority for the drain.

Case & protocol details

Classification Signature verification / token approval abuse
Protocol Type Lending
Implementation language Solidity
Official Website dolomite.io/
Protocol Twitter/X @Dolomite_io

How it happened

The exploiter submitted invalid orders together with two valid orders. The invalid orders initiated victim margin deposits through SoloMargin, then a crafted state caused Loopring's OrderHelper to skip signature verification for partially filled orders. The valid ring exchanged approved victim assets for tiny LRC amounts.

The vulnerable legacy Trade Delegate was disabled within an hour. Dolomite recovered 90% of assets and made up the remaining 10% from treasury, completing victim reimbursements on March 26.

Security review history

Funds Recovery

100.0%

Recovered

$1.8M

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.